ietf-asrg
[Top] [All Lists]

Re: [Asrg] porkhash: flexible anti-impersonation mail signatures

2003-04-03 01:49:30
This is not unique to porkhash, many if not majority of proposals either 
directly or indirectly rely on source or some central server being 
reachable for confirmation (all certificate based proposals, my callback 
verification proposals, RMX - have to have working dns server, etc.)

But to be more exactly on porkhash, you do not need to have your end to 
have persistent connection, what you need is to have verification server 
available somwhere and it be contracted by the source (server does not have 
to be same machine or even same ip network as source - can be futher 
upstream). For destination, you do checking on email when you're 
receiving it, so once ETRN is then time when destination has connection 
to internet and can verify email.
 
This is also a problem with porkhash: it disenfranchises those without
persistent connections (eg much of the third world).  There's still a
heck of a lot of mail tunneled over UUCP these days, or which relies on
disconnected ETRN semantics.


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg